Design security solutions for infrastructure
Network Security and Security Service Edge
CoreEvaluate segmented network designs and identity-centric SSE patterns for internet, Microsoft-service, and private-application traffic across users, branches, and tenants.
Aligned to SC-100 skills measured as of October 21, 2026; candidates testing earlier should review the transition note in the lane overview.
Why this matters
Network location alone is weak evidence of trust. Modern designs combine segmentation, private connectivity, inspected egress, identity-aware access, device and risk signals, and explicit cross-tenant controls at the traffic path that owns enforcement.
Must Know
- Evaluate network architecture for segmentation, ingress and egress control, private connectivity, DNS, route intent, inspection placement, resilience, logging, and operational ownership.
- Microsoft Entra Internet Access for all apps provides an identity-centric secure web gateway for internet and SaaS traffic, including web content filtering and security profiles.
- The Microsoft traffic profile secures supported Microsoft service traffic and can support compliant-network enforcement and Universal Tenant Restrictions for cross-tenant control.
- Microsoft Entra Private Access provides identity-aware access to defined private applications through connectors, avoiding broad network-level access granted by traditional VPN designs.
- Traffic forwarding profiles determine which Microsoft, private, or internet flows enter Global Secure Access; forwarding alone does not authorize access to every destination.
- SSE complements rather than automatically replaces workload network controls, service firewalls, private endpoints, and east-west segmentation.
Compare and Distinguish
- Internet Access protects public internet and SaaS traffic; the Microsoft traffic profile specializes in supported Microsoft services; Private Access brokers defined private resources.
- ZTNA grants application-specific access based on identity context, while a traditional VPN commonly extends broader network reachability.
Scenario examples
- Scenario: Remote users need only two internal applications and access must depend on device compliance. Think: publish those private resources through Entra Private Access and enforce identity-aware application access.
- Scenario: Users must reach corporate Microsoft services but not personal or unapproved tenants. Think: use the Microsoft traffic profile with Conditional Access and Universal Tenant Restrictions.
Exam traps
- Enabling a forwarding profile captures traffic but does not create destination definitions, assignments, or application authorization.
- Moving user egress to SSE does not remove the need to protect public workload origins and internal east-west paths.
Key takeaways
- Internet, Microsoft-service, and private-resource traffic require different forwarding profiles.
- A forwarding profile captures traffic; destination definition and access policy authorize it.
- SSE protects user and branch paths, not Azure workload east-west traffic by implication.
How it works
- Clients or remote networks forward selected traffic to the service edge, which evaluates profiles and associated identity-aware policies.
- Private Network Connectors broker outbound connections to configured private resources so inbound exposure is not required.
Objects and administrative surfaces
- Virtual networks, subnets, routes, firewalls, WAFs, private endpoints, DNS, DDoS controls, flow logs, and central inspection hubs.
- Global Secure Access clients and connectors, traffic profiles, enterprise applications, Quick Access definitions, security profiles, Conditional Access, and tenant restrictions.
When to use it
- Use SSE when user and branch access policy must follow identity and device context beyond a corporate perimeter.
Security and governance implications
- Govern destination definitions, TLS inspection policy, privacy, exception handling, tenant restrictions, and connector resilience before broad rollout.
Troubleshooting signals
- If traffic bypasses controls, verify client health, profile assignment, acquisition rules, route conflicts, and forwarding precedence.
- If a private app is unreachable, inspect its Quick Access or enterprise-app definition, connector group, assignments, DNS, and backend reachability.
More detail
- Evaluate conventional network design against explicit security requirements.
- Choose Internet Access modes for public and Microsoft traffic.
- Use Private Access for application-specific private connectivity.
Ready for the quiz?
- Which profile handles a private line-of-business application?
- What prevents data transfer to an unapproved Microsoft tenant?
- Which controls remain inside a workload after adopting SSE?
Related objectives
- D3.4.S1 — Evaluate network designs to align with security requirements and best practices
- D3.4.S2 — Evaluate solutions that use Microsoft Entra Internet Access as a secure web gateway
- D3.4.S3 — Evaluate solutions that use Microsoft Entra Internet Access for Microsoft Services, including cross-tenant configurations
- D3.4.S4 — Evaluate solutions that use Microsoft Entra Private Access